← China Financial Certification Authority (CFCA) cases
Bugzilla #2067050 Ca Certificate Compliance Incident Self Reported Incident Certificate Misissuance Opened By Ca

CFCA self-reported cross-signed certificate missing required EKU extension

ASSIGNED China Financial Certification Authority (CFCA)
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

CFCA reported a compliance incident involving a cross-signed certificate created when a multipurpose root certificate was used to cross-sign a dedicated root certificate. CFCA said the resulting cross-signed certificate did not include the Extended Key Usage (EKU) extension, which it stated was required in this situation. The report cites CCADB Section 6.3 on cross-certification across PKI hierarchies and notes that the dedicated root’s subordinate CAs correctly assert EKU consistent with the dedicated purpose. The bug was opened by CFCA itself as a preliminary incident report, and the thread shown does not include a final resolution. The case remains assigned to CFCA contact d**********o@cfca.com.cn.

Model: gpt-5.4-mini Generated: 2026-09-06 10:58 UTC Confidence: 0.98 1 comment
Chronology
  1. CFCA created a cross-signed certificate from a multipurpose root to a dedicated root without including the EKU extension.
Thread Activity
  1. China Financial Certification Authority (CFCA) — CFCA filed a preliminary incident report stating that the cross-signed certificate lacked the required EKU extension and identified the disclosure as self-reported.
Participants
China Financial Certification Authority (CFCA)
External References
Similar Local Cases
#2058918 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Certificate Misissuance Opened 2026-07-29 Still Open · 79% similar
CFCA: Incorrect countryName values in OV subscriber certificates
#2033412 RESOLVED Ca Certificate Compliance Externally Reported Incident Incident Certificate Misissuance Opened 2026-04-20 · Closed 2026-06-25 · 79% similar
CFCA: CRL signatureAlgorithm Missing NULL Parameter (RFC 4055 Section 5)
#1532559 RESOLVED Certificate Misissuance Self Reported Incident Opened 2019-03-05 · Closed 2023-02-22 · 78% similar
CFCA: Wrong SerialNumber encoding
#2005399 RESOLVED Incident Self Reported Incident Opened 2025-12-11 · Closed 2026-02-18 · 78% similar
CFCA: DV OCA caIssuers Returns PEM Encoded Certificate (RFC 5280 Section 4.2.2.1 Violation)
#2031281 RESOLVED Ca Certificate Compliance Self Reported Incident Incident Certificate Misissuance Opened 2026-04-13 · Closed 2026-06-16 · 78% similar
CFCA: OCSP Responder Certificate Profile Deviations and OCSP Service Issues
#1532113 RESOLVED Certificate Misissuance Self Reported Incident Opened 2019-03-03 · Closed 2023-02-22 · 77% similar
CFCA: O > 64 characters
#2026351 RESOLVED Self Reported Incident Certificate Misissuance Opened 2026-03-25 · Closed 2026-05-18 · 73% similar
Identrust: Root CrossSign, of dedicated Roots, missing EKU
#2065616 ASSIGNED Ca Certificate Compliance Self Reported Incident Incident Audit Finding Opened 2026-08-21 Still Open · 71% similar
IdenTrust: Expired certificates for "Revoked" test websites

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action